Vulnerability Description
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Java System Directory Proxy Server | 5.2 |
| Sun | Java System Directory Server | 5.2 |
| Sun | One Administration Server | 5.2 |
| Sun | One Directory Server | 4.16 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=112862037500012&w=2
- http://marc.info/?l=bugtraq&m=113815459026080&w=2
- http://secunia.com/advisories/17092Vendor Advisory
- http://secunia.com/advisories/18590Vendor Advisory
- http://securityreason.com/securityalert/367
- http://securityreason.com/securityalert/51
- http://securitytracker.com/id?1015014
- http://securitytracker.com/id?1015536
- http://securitytracker.com/id?1015537
- http://securitytracker.com/id?1015538
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-117665-03-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1
- http://www.securityfocus.com/bid/15013
- http://www.securityfocus.com/bid/16345
FAQ
What is CVE-2005-3269?
CVE-2005-3269 is a vulnerability with a CVSS score of 7.5 (HIGH). Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate S...
How severe is CVE-2005-3269?
CVE-2005-3269 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3269?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Java System Directory Proxy Server, Sun Java System Directory Server, Sun One Administration Server, Sun One Directory Server.